Computational Cluster Multi-Domain Access via Merged Authentication Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computational clusters face difficulties in configuring access to multiple domains, isolating users and services, and securing critical accounts across different domains, due to challenges in managing access and authentication.

Innovation Solution

A method and system using a ticket-based computer network authentication protocol to generate and merge keys for multiple domains, activating a system daemon to provide access, and authenticating cluster access requests across primary and secondary domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a computational cluster is configured for access to multiple domains, then the cluster can access users and services across different domains, but the complexity of managing access and authentication increases

Engineering Contradiction:
Improveaccess to multiple domainsVSAvoidaccess management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges multiple domain credentials into a single credential store, allowing the computational cluster to access multiple domains using unified authentication mechanisms rather than managing separate credentials for each domain

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces an intermediary authentication service that mediates between the computational cluster and multiple domains, handling the complexity of cross-domain authentication while presenting a simplified interface to the cluster

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If domain credentials are stored for multiple domains, then the cluster can authenticate across domains, but the security risk of storing multiple sets of credentials increases

Engineering Contradiction:
Improvecross-domain authenticationVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts domain credentials from the computational cluster and stores them in a separate, dedicated credential store, isolating the security risk away from the cluster itself while maintaining authentication capabilities

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements temporary, session-based credentials that are automatically invalidated after use, replacing the need to store long-term credentials for multiple domains and reducing the window of vulnerability

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Adaptability or versatility

If a system daemon is activated to manage multiple domain credentials, then authentication across domains is enabled, but the resource consumption increases

Engineering Contradiction:
Improvemulti-domain access capabilityVSAvoidresource consumption
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The system daemon implements periodic credential validation and rotation, actively managing credentials only when needed for authentication rather than continuously processing all domain access requests

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The credential store is designed to automatically manage its own credentials through self-service mechanisms including automatic validation, rotation, and revocation, reducing the computational overhead on the system daemon

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20240396885A1System, Method, and Computer Program Product for Managing Computational Cluster Access to Multiple Domains
Publication Date: 2024.11.28 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US20240396885A1 patent drawing
  • US20240396885A1 patent drawing
  • US20240396885A1 patent drawing

AI summary

A computer-implemented method for managing computational cluster access to multiple domains includes generating, using a ticket-based computer network authentication protocol, a primary set of keys based on remote system access credentials for a primary domain and a secondary set of keys based on remote system access credentials for a secondary domain. The method includes merging the primary set of keys with the secondary set of keys to form a merged set of keys. The method further includes activating a system daemon to provide access to the primary domain and the secondary domain by a computational cluster based on the merged set of keys. The method further includes connecting, using the ticket-based computer network authentication protocol via the system daemon, a remote computing device of the primary domain and a remote computing device of the secondary domain to the computational cluster.